> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security overview

> Fini's certifications, encryption, data residency, hosting and legal terms in one table, plus the product controls your team configures and where to get audit reports.

Fini (usefini.com) is SOC 2 Type II compliant, ISO/IEC 27001:2022 certified, PCI DSS Level 1 certified, HIPAA-compliant and BAA-eligible, and supports GDPR and CCPA obligations. Customer data is encrypted with AES-256 at rest and TLS 1.2+ in transit, stays in your choice of US or EU region, and Fini does not use customer data to train foundation models.

This page is written for security, privacy and procurement reviewers. It summarizes Fini's posture, tells you where to get the evidence (audit reports, pen-test report, DPA), and lists the controls your own team configures inside the product. Fini's policies and reports live in the [Trust Center](https://security.usefini.com/); this page links to them rather than restating them.

## Posture at a glance

| Area | Fini position | Source of record |
| - | - | - |
| Certifications and attestations | SOC 2 Type II compliant, ISO/IEC 27001:2022 certified, PCI DSS Level 1 certified | [Trust Center](https://security.usefini.com/) (reports on request). See [SOC 2 Type II and ISO 27001](/en/security/soc2-iso27001). |
| Payment card data | PCI DSS Level 1 certified. Card numbers are masked automatically in stored conversation data. | See [PCI DSS](/en/security/pci-dss). Request the attestation (AOC) from your Fini account team. |
| Privacy frameworks | GDPR, CCPA | [Data Processing Addendum](https://www.usefini.com/security/data-processing-addendum), [Privacy policy](https://www.usefini.com/security/privacy-policy) |
| Healthcare | HIPAA-compliant and BAA-eligible | See [HIPAA and BAAs](/en/security/hipaa) |
| Encryption | AES-256 at rest, TLS 1.2+ in transit | Trust Center |
| Data residency | Customer-designated region: United States or European Union. With EU data residency, data is stored and processed in the EU. | DPA, [Data handling](/en/security/data-handling#where-data-is-processed) |
| Hosting | Google Cloud. Azure-hosted deployment is available through Microsoft Marketplace, running in your Azure tenant. | Trust Center, [Fini on Microsoft Azure](https://www.usefini.com/better-together) |
| Model training | Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer's environment and only with their written authorization. LLM subprocessors are contractually barred from training on it. | DPA |
| Sensitive data masking | Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps | See [Data handling](/en/security/data-handling#masking-sensitive-data) |
| Subprocessors | Google Cloud (including Gemini), Microsoft Azure, Supabase, OpenAI, Anthropic, PostHog, Sentry, Stripe, Linear, Google (email) and Langfuse; 30 days' notice of changes. Purposes are listed in [Data handling](/en/security/data-handling#subprocessors). | DPA, Trust Center |
| Single sign-on | Okta, Google, Slack and Microsoft Entra ID (the setup guide covers Okta) | [Okta SSO](/en/sso-login) |
| Access controls | Role-based access internally; workspace-scoped API keys with `read` and `write` scopes | [Data protection policy](https://www.usefini.com/security/data-protection-policy), [API keys](/en/deploy/api-keys) |
| Penetration testing | Annual third-party penetration testing; pen-test report available on request | Trust Center |
| Breach notification | Within 72 hours | DPA |
| Uptime target | 99.9% monthly | [Terms of service](https://www.usefini.com/security/terms-of-service) |
| Recovery Time Objective | 24 to 48 hours | Trust Center risk profile |
| Data retention | You set your own retention period; deletion removes all data. Deletion APIs available. | See [Data handling](/en/security/data-handling#retention-and-deletion) |
| Audit logs | Customers can export audit logs | Trust Center |
| Cyber insurance | In place; the **Cyber Insurance** document is available on request | Trust Center |

The Trust Center risk profile also classifies Fini at **Data Access Level: Internal** and **Impact Level: Moderate**. Use those values if your vendor-risk tool asks for the vendor's self-assessed tier.

## Getting the evidence

Fini's Trust Center at [security.usefini.com](https://security.usefini.com/) is the single place for security documentation. Public sections cover product security, data security, app security, infrastructure, endpoint, network and corporate security, legal, and policies. Sensitive documents are gated and released on request.

<Steps>
  <Step title="Open the Trust Center">
    Go to [security.usefini.com](https://security.usefini.com/) and click **Get access** (or **Start your security review**).
  </Step>

  <Step title="Request the documents you need">
    The featured documents are the **Pentest Report**, **ISO/IEC 27001**, **SOC 2**, **Cyber Insurance** and **Data Processing Agreement**. The Reports section also lists a **Network Diagram**, and Self-Assessments include a **VSA Full** questionnaire.
  </Step>

  <Step title="Ask follow-up questions">
    Use **Ask for information** in the Trust Center for anything not covered by the documents. Report a suspected vulnerability with **Report issue**.
  </Step>
</Steps>

<Tip>
  Start with the VSA Full self-assessment and the SOC 2 report before sending your own questionnaire. Many questions in a standard vendor security questionnaire are answered there already, so your follow-up list is shorter.
</Tip>

Legal terms are published on usefini.com:

* [Data Processing Addendum](https://www.usefini.com/security/data-processing-addendum) (v1.0.5)
* [Privacy policy](https://www.usefini.com/security/privacy-policy) (v1.0.5)
* [Data protection policy](https://www.usefini.com/security/data-protection-policy) (v1.0.4)
* [Terms of service](https://www.usefini.com/security/terms-of-service) (v1.0.6)

For legal and privacy questions, contact [legal@usefini.com](mailto:legal@usefini.com).

## Controls your team configures

Certifications cover how Fini runs its platform. The controls below are the ones you own inside your workspace. A security review is stronger when it covers both.

```mermaid theme={null}
---
title: Security layers, who runs each one
---
flowchart TD
    subgraph FINI["FINI RUNS"]
        CERT["Assurance<br/>SOC 2 Type II · ISO/IEC 27001:2022<br/>PCI DSS Level 1 · annual pen test"]
        INFRA["Infrastructure<br/>Google Cloud, US or EU region<br/>Azure option via Marketplace"]
        DATA["Data protection<br/>AES-256 at rest · TLS 1.2+<br/>sensitive data masking · no foundation-model training"]
        LEGAL["Contract terms<br/>DPA · 72-hour breach notice<br/>30-day subprocessor notice"]
    end

    subgraph YOU["YOUR TEAM CONFIGURES"]
        ACCESS["Access<br/>SSO · API key scopes<br/>static IP allowlist"]
        BEHAVE["Agent behavior<br/>Guardrails · Reply Rules<br/>Rulebook Tool nodes"]
        AUDIT["Audit and data<br/>AI Steps · audit log export<br/>retention period · deletion API"]
    end

    CERT ~~~ INFRA ~~~ DATA ~~~ LEGAL
    LEGAL ~~~ ACCESS
    ACCESS ~~~ BEHAVE ~~~ AUDIT

    classDef source fill:#F7F7F7,color:#131415,stroke:#E8E8E8
    classDef agent fill:#131415,color:#FFFFFF,stroke:#131415,stroke-width:3px
    classDef surface fill:#FFFFFF,color:#131415,stroke:#131415
    classDef human fill:#C3EE5E,color:#131415,stroke:#131415,stroke-width:2px

    class CERT,INFRA,DATA,LEGAL agent
    class ACCESS,BEHAVE,AUDIT human
```

| Control | What it does | Where |
| - | - | - |
| Single sign-on | Your team signs into the Fini dashboard with Okta, Google, Slack or Microsoft Entra ID. With Okta, only users assigned to the SAML app can sign in, so offboarding in your IdP removes access. | [Okta SSO](/en/sso-login) |
| API key scopes | Workspace keys carry `read`, `write` or both. Keys are shown once, can be revoked individually, and revocation is immediate. Keep `write` off for export-only integrations. | [API keys](/en/deploy/api-keys) |
| Static outbound IPs | When an Action calls your systems, the request originates from four fixed IP addresses in Google Cloud's europe-west4 region (Netherlands), for every workspace. You can allowlist them on port 443. | [Static IP addresses](/en/api-reference/static-ip) |
| Guardrails | An extra layer on top of automatic masking. Checks run on every generated reply before delivery: **Confidential attributes** (values of selected user attributes must not appear in replies), **Banned terms**, **URL allowlist**, **AI disclosure**, **Internal reasoning leak**, and up to 10 **Custom rule** checks. | [Guardrails](/en/configuration/guardrails) |
| Reply Rules | Decide per conversation whether the agent sends a **Direct Reply**, leaves an **Internal Comment** for your team only, or sends **No Reply**. The stricter behavior always wins. | [Reply Rules](/en/automations/reply-behavior) |
| Deterministic workflows | Actions run only when a **Tool** node in a published Intent Rule or Business Rule invokes them, so the agent cannot call an API outside a rule you built and tested. | [Rulebook](/en/automations/rulebook), [Actions](/en/api-reference/actions) |
| Audit trail | Every Fini reply has an **AI Steps** trace: knowledge retrieved, rules and nodes executed, user attributes loaded, tags applied, guardrail verdicts and the model's reasoning. | [Inbox](/en/testing/inbox) |
| Regression testing | Conversation-based test cases with AI-judged and exact criteria, run against recorded or mock Action responses before you ship changes. | [Test Suite](/en/testing/test-suite) |
| Data deletion | Delete one conversation, or up to 50 per request, through the public API with a `write`-scoped key. | [Delete conversation](/en/api-reference/delete-conversation), [Bulk delete conversations](/en/api-reference/bulk-delete-conversations) |

<Warning>
  Guardrails are not a fail-closed security boundary. If a check errors or times out, the original reply can be sent unchanged. Treat Guardrails as one layer alongside Reply Rules, Rulebook design and Test Suite coverage, and review per-check verdicts in AI Steps. See [Guardrails](/en/configuration/guardrails#reply-outcomes).
</Warning>

## Reviewer FAQ

<AccordionGroup>
  <Accordion title="Does Fini train AI models on our data?">
    No. Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer's environment and only with their written authorization. Fini's LLM subprocessors are contractually barred from training on it. This commitment is in the [DPA](https://www.usefini.com/security/data-processing-addendum). See [Data handling](/en/security/data-handling#model-training).
  </Accordion>

  <Accordion title="Where is our data stored?">
    In the region you designate: the United States or the European Union. With EU data residency, data is stored and processed in the EU. Fini runs on Google Cloud. If you buy through Microsoft Marketplace, Fini can run on Azure in your own tenant, with Private Link, VNet support, customer-managed encryption keys, Entra ID and Conditional Access. See [Data handling](/en/security/data-handling#where-data-is-processed).
  </Accordion>

  <Accordion title="Which identity providers work for SSO?">
    Fini supports single sign-on with Okta, Google, Slack and Microsoft Entra ID. The setup guide covers Okta step by step: [Okta SSO](/en/sso-login).
  </Accordion>

  <Accordion title="Who are Fini's subprocessors?">
    Google Cloud (including Gemini) for hosting and AI, Microsoft Azure for Azure Marketplace deployments (including Azure AI Foundry and Azure OpenAI), Supabase as the managed database, OpenAI and Anthropic for LLM inference under enterprise agreements, PostHog for product analytics (usage metrics only), Sentry for error monitoring and logging, Stripe for billing, Linear for issue tracking, Google for email, and Langfuse for tracing. Fini gives 30 days' notice of subprocessor changes under the [DPA](https://www.usefini.com/security/data-processing-addendum). See [Data handling](/en/security/data-handling#subprocessors).
  </Accordion>

  <Accordion title="How fast will Fini tell us about a breach?">
    Within 72 hours, under the [DPA](https://www.usefini.com/security/data-processing-addendum).
  </Accordion>

  <Accordion title="Can the AI agent take actions we haven't approved?">
    No. An Action runs only when a **Tool** node in a published rule invokes it, and Intent Rule execution is deterministic: the same conversation context produces the same tree walk. You decide which Actions exist, which rules call them, and which agents those rules are assigned to. Every Action call is recorded in the AI Steps trace. See [Rulebook](/en/automations/rulebook).
  </Accordion>

  <Accordion title="How do we audit what the agent said and why?">
    Open the conversation in [Inbox](/en/testing/inbox) and click the light bulb icon on any Fini reply. The **AI Steps** sidebar shows Planning, Executed User Attributes, Executed Rule, Generate Answer, tag selection with reasoning, and Guardrails verdicts, in execution order.
  </Accordion>

  <Accordion title="Can we delete conversation data?">
    Yes. You set your own retention period, and deletion removes all data. Delete through the [Delete conversation](/en/api-reference/delete-conversation) and [Bulk delete conversations](/en/api-reference/bulk-delete-conversations) endpoints, or by request. See [Data handling](/en/security/data-handling#retention-and-deletion).
  </Accordion>

  <Accordion title="Does Fini store card numbers or health data from conversations?">
    Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Design workflows so card numbers, CVVs and health details never need to enter the conversation: don't ask customers for them, and route card actions through your payment provider via [Actions](/en/api-reference/actions). Configure [Guardrails](/en/configuration/guardrails) as an extra layer. See [Data handling](/en/security/data-handling#masking-sensitive-data).
  </Accordion>

  <Accordion title="Can we export audit logs?">
    Yes. Customers can export audit logs. For reply-level reasoning, use the **AI Steps** trace in [Inbox](/en/testing/inbox).
  </Accordion>

  <Accordion title="Do you have a completed security questionnaire?">
    Yes. A VSA Full self-assessment is listed in the [Trust Center](https://security.usefini.com/). See also [Security questionnaire](/en/evaluate/security-questionnaire).
  </Accordion>
</AccordionGroup>

## Related

<CardGroup cols={2}>
  <Card title="Data handling, residency and model training" icon="database" href="/en/security/data-handling">
    What Fini processes, where, for how long, and under which DPA terms.
  </Card>

  <Card title="SOC 2 Type II and ISO 27001" icon="certificate" href="/en/security/soc2-iso27001">
    What Fini holds and how to request the reports.
  </Card>

  <Card title="PCI DSS" icon="credit-card" href="/en/security/pci-dss">
    Fini's PCI DSS Level 1 certification and how to keep card actions in your payment systems.
  </Card>

  <Card title="HIPAA and BAAs" icon="notes-medical" href="/en/security/hipaa">
    Requesting a BAA and configuring Fini for protected health information.
  </Card>

  <Card title="Regulated industries: disputes and complaints" icon="scale-balanced" href="/en/security/regulated-industries-disputes-complaints">
    Capture, tag, escalate and audit complaint and dispute conversations.
  </Card>
</CardGroup>


## Related topics

- [Security questionnaire answers](/en/evaluate/security-questionnaire.md)
- [SOC 2 Type II and ISO 27001](/en/security/soc2-iso27001.md)
- [HIPAA and BAAs](/en/security/hipaa.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.